Reichel, D. (2021, February 19). IronNetInjector: Turla’s New Malware Loading Tool. Retrieved February 24, 2021.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.013 Encrypted/Encoded File |
ToolIronNetInjector | IronNetInjector can obfuscate variable names, encrypt strings, as well as base64 encode and Rijndael encrypt payloads. |
| T1036.004 Masquerade Task or Service |
ToolIronNetInjector | IronNetInjector has been disguised as a legitimate service using the name PythonUpdateSrvc. |
| T1053.005 Scheduled Task |
ToolIronNetInjector | IronNetInjector has used a task XML file named |
| T1055 Process Injection |
ToolIronNetInjector | IronNetInjector can use an IronPython scripts to load a .NET injector to inject a payload into its own or a remote process. |
| T1055.001 Dynamic-link Library Injection |
ToolIronNetInjector | IronNetInjector has the ability to inject a DLL into running processes, including the IronNetInjector DLL into explorer.exe. |
| T1057 Process Discovery |
ToolIronNetInjector | IronNetInjector can identify processes via C# methods such as |
| T1059.006 Python |
ToolIronNetInjector | IronNetInjector can use IronPython scripts to load payloads with the help of a .NET injector. |
| T1059.006 Python |
GroupTurla | Turla has used IronPython scripts as part of the IronNetInjector toolchain to drop payloads. |
| T1140 Deobfuscate/Decode Files or Information |
ToolIronNetInjector | IronNetInjector has the ability to decrypt embedded .NET and PE payloads. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.